generated: '2026-08-04' method: searched source: >- openapi/harbinger-health-wordpress-wp-v2-openapi.yml, the RFC 8414 and RFC 9728 documents served by the host, live header/payload probes on 2026-08-04, and the compliance statement published in the site footer standards: - id: oauth2 conforms: true evidence: >- RFC 6749 authorization-code grant with refresh tokens, declared at https://harbinger-health.com/.well-known/oauth-authorization-server. - id: oauth2.1-pkce conforms: true evidence: 'code_challenge_methods_supported: [S256]; token_endpoint_auth_methods_supported: [none] (public clients).' - id: rfc8414-as-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 application/json with issuer and endpoints. - id: rfc9728-protected-resource-metadata conforms: true evidence: >- /.well-known/oauth-protected-resource returns 200 naming https://harbinger-health.com/wp-json/mcp/mcp-oauth-server with authorization_servers and bearer_methods_supported. - id: model-context-protocol conforms: true evidence: >- Two MCP servers registered at /wp-json/mcp/; JSON-RPC 2.0 over HTTP; anonymous tools/list returns the MCP-specific 401 mcp_unauthorized rather than a generic WordPress error. caveat: Tool catalogue not observable anonymously, so protocol version and capabilities are unverified. - id: rfc8288-web-linking conforms: true evidence: 'Link header with rel="next" observed on wp/v2 collection reads; every resource carries _links.' - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404. No identity layer is advertised. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json anywhere. Errors use the WordPress code/message/data envelope — see errors/harbinger-health-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404. - id: a2a-agent-card conforms: false evidence: Both /.well-known/agent-card.json and /.well-known/agent.json return 404. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header on any probed response. - id: openapi conforms: false evidence: >- Harbinger Health publishes no OpenAPI. The document in openapi/ was derived by API Evangelist from the WordPress route-discovery document and is not a provider artifact. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface exists on any host. - id: graphql conforms: false evidence: /graphql returns 404. - id: fhir conforms: false evidence: >- No FHIR resource shapes, no /fhir base, no CapabilityStatement. Despite being a clinical diagnostics company, Harbinger Health exposes no health-data interoperability surface at all. - id: hl7-v2 conforms: false evidence: No HL7 interface is published or referenced. - id: phenopackets conforms: false evidence: No GA4GH or genomics interchange format is published. - id: scim conforms: false - id: odata conforms: false - id: json-api conforms: false industry_compliance: published: true source: https://harbinger-health.com/resolve/ statement: >- "Harbinger health laboratory is CLIA certified and CAP accredited, meeting all nationally recognized standards for high complexity testing. All testing performed using validated methods." — published in the site-wide footer on every page. credentials: - {id: clia, name: Clinical Laboratory Improvement Amendments certification, scope: high-complexity clinical laboratory, verified_by: provider statement} - {id: cap, name: College of American Pathologists accreditation, scope: laboratory accreditation, verified_by: provider statement} not_published: - {id: soc2, note: No SOC 2 report or trust centre is referenced anywhere on the site.} - {id: iso27001, note: Not referenced.} - {id: hipaa, note: 'No HIPAA statement, BAA offer or notice of privacy practices is published, despite operating a clinical laboratory.'} - {id: fedramp, note: Not applicable / not referenced.} - {id: gdpr, note: Not referenced in the compliance footer.} note: >- These are laboratory credentials, not information-security certifications, and they say nothing about the API surface catalogued in this repository. They are recorded because they are a real, published compliance posture — and they are what the Compliance pointer in apis.yml refers to.